CVE-2026-63406Medium· 5.9▾ TwilightPoC availableAnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 32.5 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in telemetry/telemetry.go reads the full configuration file and raw os.Args returned by anycableCLIArgs, including values supplied through --secret, --jwt_secret, and --http_rpc_secret. These inputs are passed to generateDigest, where sha256.New produces the hexadecimal fingerprint that is sent as telemetry. The available source therefore does not show raw credentials leaving the process or establish the advisory's claimed confidentiality loss, although the stable fingerprint is derived from secret-bearing configuration and the default telemetry client uses publicly known authentication material. This issue is fixed in version 1.6.15.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/anycable/anycable <= 1.6.14Patched in:
github.com/anycable/anycable 1.6.15Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63405Medium· 5.9AnyCable is a realtime server for reliable two-way communication that supports any backend
CVE-2019-6693Medium· 6.5Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key
CVE-2026-57148Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57147Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-42151High· 7.5Prometheus is an open-source monitoring system and time series database
CVE-2026-54767Critical· 9.1WeGIA is a web manager for charitable institutions